CVE-2026-90439

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-15: 1Mentions · 2026-09-16: 109-1509-16
Referenced assets2 URLs
Full discourse2 posts
  • Frank@jedisct1

    nginx 1.31.6 released - Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439). https://nginx.org/en/CHANGES

    0301951.8K
    17.7K followersView on X
  • 현빈 | Hyunbin@hyunbinseo97

    > nginx-1.30.5 stable version has been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module (CVE-2026-90439). > The ngx_http_v3_module module (1.25.0) provides experimental support for HTTP/3. https://github.com/nginx/nginx/releases/tag/release-1.30.5

    00010156
    3.6K followersView on X

Explore more